cleantalk
Vulnerabilities and Security Researches

StaffList, CVE-2022-1556

CVE, Research URL

CVE-2022-1556

Application

StaffList

Published on
May 30, 2022
Research Description
The StaffList WordPress plugin before 3.1.5 does not properly sanitise and escape a parameter before using it in a SQL statement when searching for Staff in the admin dashboard, leading to an SQL Injection
Affected versions
Min -, max 3.1.5.
Status
vulnerable